Overview
On Site
USD 74,922.00 - 149,843.00 per year
Full Time
Skills
Healthcare Information Technology
Security Controls
Risk Management
Risk Analysis
Risk Management Framework
Authorization
Documentation
System Security
Regulatory Compliance
Auditing
Leadership
Cyber Security
Data Security
Management
Access Control
Identity Management
IT Security
Physical Security
Information Security
HIS
Immigration
CISSP
Insurance
Reporting
Network
Job Details
The Senior IT Security Analyst -Risk Management is a highly skilled and technically proficient member of the Cybersecurity Operations team within the University of Virginia Health System Health IT (HIT) organization. This role is critical in deploying, configuring, operating, troubleshooting, and evaluating the effectiveness of a wide array of cybersecurity controls and services. The ideal candidate will have deep technical expertise and a passion for defending complex environments against evolving cyber threats.
Key Responsibilities:
Assess the effectiveness of security controls
Perform security reviews
Work with Leadership to develop a cybersecurity risk management plan
Recommend risk mitigation strategies
Conduct risk analysis of applications and systems undergoing major changes
Advise on Risk Management Framework process activities and documentation
Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
Update security documentation to reflect current application and system security design features
Document software, network, and system deviations from implemented security postures
Recommend required actions to correct software, network, and system deviations from implemented security postures
Work with Leadership to develop cybersecurity compliance processes for external services
Work with Leadership to develop cybersecurity audit processes for external services
Work with Leadership to provide cybersecurity guidance to organizational risk governance processes
Determine if vulnerability remediation plans are in place
Develop vulnerability remediation plans
Determine if cybersecurity requirements have been successfully implemented
MINIMUM REQUIREMENTS
Education: Bachelor's degree
Experience: 5-7 years relevant experience. Relevant experience may be considered in lieu of a degree.
Licensure: CISSP or HCISPP or similar preferred.
PHYSICAL DEMANDS
This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings, and programs.
Position Compensation Range: $74,922.00 - $149,843.00 Annual
Benefits
Key Responsibilities:
Assess the effectiveness of security controls
Perform security reviews
Work with Leadership to develop a cybersecurity risk management plan
Recommend risk mitigation strategies
Conduct risk analysis of applications and systems undergoing major changes
Advise on Risk Management Framework process activities and documentation
Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
Update security documentation to reflect current application and system security design features
Document software, network, and system deviations from implemented security postures
Recommend required actions to correct software, network, and system deviations from implemented security postures
Work with Leadership to develop cybersecurity compliance processes for external services
Work with Leadership to develop cybersecurity audit processes for external services
Work with Leadership to provide cybersecurity guidance to organizational risk governance processes
Determine if vulnerability remediation plans are in place
Develop vulnerability remediation plans
Determine if cybersecurity requirements have been successfully implemented
- Maintenance of data security tables and files used to manage for access controls and identity management systems.
- Assists with investigative process during computer security incident responses.
- Implements and maintains information security infrastructure.
- Collaborates with other HSCS teams to ensure Information Security Plan and Standards are implemented.
- Collaborates with other HSCS teams to ensure facility and physical security is implemented. Coordinates Information Security Awareness program and educational activities.
- In addition to the above job responsibilities, other duties may be assigned.
MINIMUM REQUIREMENTS
Education: Bachelor's degree
Experience: 5-7 years relevant experience. Relevant experience may be considered in lieu of a degree.
Licensure: CISSP or HCISPP or similar preferred.
PHYSICAL DEMANDS
This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings, and programs.
Position Compensation Range: $74,922.00 - $149,843.00 Annual
Benefits
- Comprehensive Benefits Package: Medical, Dental, and Vision Insurance
- Paid Time Off, Long-term and Short-term Disability, Retirement Savings
- Health Saving Plans, and Flexible Spending Accounts
- Certification and education support
- Generous Paid Time Off
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.